The Changelog: Software Development, Open Source · Changelog Media

Securing npm is table stakes (Interview)

January 29, 2026·1 hr 21 min·6 clips
Adam identifies the structural problem: credit card companies have financial incentive to prevent fraud, but npm is a cost sink for Microsoft with no revenue tied to package integrity.
The concern is basic. Jared brings in Nicholas, the creator and longtime maintainer of ESLint, as someone with enough scar tissue to talk plainly about GitHub's npm response. Security is the floor here. Nicholas gives PNPM credit for trying a client-side delay on packages newer than about seven days, even if he is careful not to oversell the impact. The speed mattered. Next to that, npm's response sounds to him like work GitHub already had planned, followed by a wait-and-see posture. Then the blunt question lands. If npm moves slowly on security, and the ecosystem depends on it this much, should JavaScript developers keep using it? Nicholas does not turn that into drama. His answer is mostly that npm's inertia is enormous. Leaving is hard for almost everyone. The readme still wins. Package after package tells people to install from npm, and plenty of developers do not know where else they would go. JSR comes up as the more hopeful alternative. Nicholas says he had high hopes for Deno's option because it seemed to think about security and stability early. Then reality gets in the way. npm is still the default piece of internet infrastructure that frustrated developers reach for every day. The mood is frustrated, not theatrical. The same pressure point keeps coming back: securing npm is not a nice extra, because too much software already assumes npm works. GitHub hangs over the conversation as the steward people want to see moving faster. By the end, there is no clean exit, just the unresolved question of whether npm is neglected, fixable, or exactly as messy as the drama suggests.

As heard by us

A sharp, grounded conversation about why npm security feels overdue, and why leaving npm is harder than wanting to.

NPM security lands here as infrastructure work, not routine cleanup. The episode frames the registry as a piece of JavaScript's everyday plumbing, then asks why GitHub's response still feels slower and thinner than the problem deserves.

Read the full review in PlayNext →

Why you'd press play

Press play if you want to sit with npm's massive gravity and ask whether GitHub is moving fast enough to secure it.

Read the full recommendation in PlayNext →
Listen to the show on